Privacy notice
Last updated: 9 October 2026 · Draft — pending legal review
Status of this notice
We are preparing to launch TaktBook and have not yet onboarded paying customers. This notice describes how the product is designed to handle personal data. It has not yet been reviewed by a lawyer, and the details below will change as the product and our legal entity arrangements are finalised.
Who is responsible
TaktBook is a product of Kernwerk Digital. For data relating to a business that uses TaktBook, that business is the controller and Kernwerk Digital is the processor, acting on documented instructions. Kernwerk Digital is the controller for data about the use of this website and for accounts Kernwerk Digital holds directly.
Contact: info@kernwerkdigital.com
This website
This marketing site sets no cookies, runs no analytics scripts, and loads no fonts, trackers or embedded content from third parties. Nothing about your visit is recorded or shared. If we add analytics later we will say so here and, where the law requires it, ask first.
Booking and customer data
When someone books through TaktBook we store their name, phone number, email address if they give one, the service booked, the appointment time, and any communication preferences they choose. We use it to manage the appointment and, where they have agreed, to send reminders and offers.
- Confirmations and reminders — necessary to deliver a service that has been booked. Sent without relying on marketing consent.
- Offers and rebooking prompts — sent only where the customer has opted in. No opt-in, no message.
- Service improvement — only where the customer has opted in and where the data has been anonymised.
How consent is recorded
Each consent decision is stored with its timestamp, the channel it was given on, and the version of the policy wording the customer saw. If wording changes we ask again rather than assuming the old agreement still applies. Consent can be withdrawn at any time, and withdrawal takes effect before the next message is sent rather than after it.
Consent records are retained even after withdrawal, because we need to be able to show what was agreed and when.
Who else sees this data
| Provider | Role | Location | Data |
|---|---|---|---|
| Contabo GmbH | Server hosting | Lauterbourg, France (EU) | Everything stored in the database, including booking records and consent records |
| Brevo | Transactional email delivery | Paris, France (EU) | Recipient email address, message content, delivery status |
| seven.io / SMS gateway | SMS delivery | Germany / Netherlands (EU) | Recipient phone number, message content, delivery status |
| Stripe | Subscription billing | United States / Ireland | Billing contact details, payment method references. We never see or store card numbers. |
A current list of subprocessors is maintained as our subprocessor register, which businesses on TaktBook can request.
How long we keep it
| Data | Retention |
|---|---|
| Booking and appointment records | While the business account is active |
| Customer records | 24 months after last activity, then deleted or anonymised |
| Consent records | Retained for as long as needed to demonstrate consent existed |
| Notification and message logs | 12 months |
| Audit events | 12 to 36 months depending on sensitivity |
| Billing and commission records | As required by tax and accounting law |
Where retention is shorter than the period a business or a legal obligation requires, we keep the minimum instead — for example consent records, which must outlive the data they relate to.
Your rights
Under the GDPR you can ask for access to your data, correction of anything wrong, deletion, restriction, or a copy in a portable format. You can object to processing based on legitimate interests, and you can withdraw consent at any time.
If TaktBook is being used by a business, the quickest route is to ask that business directly — they are the controller and hold your record. If you would rather go to us, or if a business does not resolve your request, email us and we will help.
You also have the right to complain to your national supervisory authority. In Slovakia that is the Úrad na ochranu osobných údajov.
Data stored in the EU
Application data, hosting, email delivery and SMS delivery are all provided within the European Union. Payment processing is provided by an American company with an Irish entity, and transfers for that part rely on an adequacy decision and standard contractual clauses.
Changes
If we change how we handle data in a way that affects you, we will update this page and, where the change relies on consent, ask you again. Changes to consent wording bump the policy version, which is recorded against each consent decision.
Contact
Kernwerk Digital · info@kernwerkdigital.com